hybridresourcing Sign up for the waitlist

Kennisbank

How mature is your privacy and security when it comes to AI

Every organization that works with AI processes data that used to be kept only internally or not kept at all. Prompts, uploads, intermediate output, log files from models you don't host yourself. The question is not whether there are risks in that, but whether your organization knows where those risks lie and who can do something about them. That is a different question from whether you have a privacy policy. Policy on paper and maturity in practice often diverge considerably with AI, because the technology changes faster than the procedures meant to guide it.

Why this dimension counts in the maturity measurement

Privacy and security are one of the seven dimensions in the maturity measurement, alongside organization, IT infrastructure, and data management, among others. The latter three are fundamental: they determine whether there is a foundation on which the rest can build. Privacy and security partly depend on that. An organization with weak data management often does not even know which data ends up in an AI application, let alone whether that happens according to the rules. That's why it makes little sense to fine-tune encryption or access management before it is clear which data is located where and who is responsible for it. The order is not a matter of preference; it is the order in which it works.

The five levels, applied to privacy and security

At baseline level, there is no explicit policy for AI and data. What happens, happens ad hoc, usually out of sight of whoever is responsible for it.

At foundation level, there is a basic policy, often taken over from existing privacy policy without being tailored to what makes AI applications different. There is awareness, but no control.

At activation level, there are concrete rules for which data may go into which AI application, and this is enforced. Access management and data classification are set up, not merely described.

At insight level, it becomes visible how AI applications actually behave in practice: which data they actually process, where discrepancies arise between policy and use. There is monitoring that yields something, not just a dashboard that nobody consults.

At intelligence level, security is built into the way new AI applications are assessed and approved before they are put into use. Risk assessment is no longer a separate step but part of how decisions are made.

Most organizations whose AI pilots get stuck turn out, on closer inspection, to be hovering between foundation and activation: there is policy, but nobody can say with certainty whether it is being followed.

Where you can see it, without measuring it

There are a few signs that, apart from any score, say something about where you stand. If nobody in your organization can pinpoint exactly which AI applications are currently in use, you are probably at baseline or foundation. If that is known but the answer to "which data is allowed in there" differs per team, you are at foundation or activation. If you know which data is allowed where, but don't know whether that is also how it goes in practice, you are at activation and insight is waiting for you. And if security is included by default with every new application, without a separate process being needed for it, you are moving toward intelligence.

This self-assessment is an indication, not a substitute for the plotting round. The value of that round lies precisely in what an individual assessment does not show: the spread. When a CISO places this dimension at activation and a department head places it at baseline, that difference is itself the information. It means that policy and practice are not aligned, or that knowledge of what is and isn't allowed has not spread equally far everywhere.

What moving up a level requires

The step from foundation to activation rarely requires a bigger budget for security software. Often it requires clear agreements about who is allowed to decide that an AI application goes into use, and on the basis of which data. That touches on how organization is structured: without a clear owner for this kind of decision, policy remains a document without enforcement. It also touches on data management, because without an overview of your data you can never say with certainty what an AI application gets to see. And it touches on ethics, because the question of what is and isn't acceptable in AI use rarely turns out to be a purely technical question.

What moving up a level costs depends on where the organization currently stands and what basic structure is already in place. An organization with good data management and a clear organizational structure needs relatively little extra work for this dimension; an organization that scores low on both fundamental dimensions will have to address those first before privacy and security improve structurally. This too is a reason why the seven dimensions cannot be read separately from one another: people and skills also play a role here, which you can read about on the page about how mature employees' knowledge of AI risks is, and on the question of how mature performance management around AI use is set up, because without follow-up even the best security policy remains theory.

The maturity measurement, including the plotting round for this and the other six dimensions, is under construction. Anyone who wants to use the measurement as soon as it becomes available can join the waiting list.

What this dimension does not answer

This page is about whether your organization can bear AI: whether the foundation is there to handle data safely and responsibly once AI touches that data. It is not about which tasks AI could take over from your employees. That question is answered by the work scan from FTE TO AI, which calculates per task which part of it can be handed over to AI. That calculation only has value if the question this page asks can already be answered with peace of mind.

Robbyde assistent van de volwassenheidsmeting

Vraag maar wat er moet staan voordat AI in uw organisatie kan landen.

Answers come from this site’s knowledge base. Not tailored advice, and not a scan of your company.